package com.dingding.controller;

import org.springframework.web.bind.WebDataBinder;
import org.springframework.web.bind.annotation.InitBinder;
import org.springframework.web.bind.annotation.RestController;

/**
 * API误用：不安全的框架绑定
 *
 * @author Dingxintao
 * @date 2023/9/25 16:22
 */
@RestController
public class BaseController {
  @InitBinder
  public void initBinder(WebDataBinder binder) {
    binder.setDisallowedFields("test");
  }
}
